ThreatCluster

Microsoft Addresses Vulnerabilities in Memory Management with CVEs

First seen 18 Feb 2026, 10:13 UTC Api.Msrc.Microsoft 41

Article Content

Browse articles
ThreatCluster

Microsoft has published information on two critical vulnerabilities affecting memory management in their systems. CVE-2024-26987, published on May 1, 2024, addresses a deadlock issue when hugetlb_optimize_vmemmap is enabled, while CVE-2025-37958, published on May 20, 2025, fixes a problem with dereferencing an invalid pmd migration entry. These vulnerabilities could impact system stability and performance.

Timeline

2024-05-01
CVE-2024-26987 published
2025-05-20
CVE-2025-37958 published
2026-02-18
Microsoft publishes information on both CVEs